About Hailstorm Core
By integrating assessment technology with a unique SmartAttack™-based approach, Cenzic Hailstorm Core provides high quality of results for assessing applications by:
- Testing commercial and custom web applications against best practice security policies
- Testing and monitoring applications for commonly known vulnerabilities
- Building security into web applications as they are being developed, greatly reducing the cost, risk, testing, and time to market.
Hailstorm Core is a simplified product based on the technology of Hailstorm enterprise. Key features include:
- Support for instant and interactive assessments
- Ability to assess sites up to 150 pages
- Support for common SmartAttack™ such as SQL Disclosure, SQL Error, Cross-site scripting, web server version, and Buffer overflow
- Consolidated assessment report output
About Hailstorm Starter
Hailstorm Starter is a simplified product based on the technology of Hailstorm Enterprise. Key features include:
- Support for instant and interactive assessments
- Ability to assess sites up to 50 pages
- Support for a common SmartAttack™: Cross-site scripting
About Hailstorm Professional
Cenzic Hailstorm Professional Edition provides rich features with unmatched extensibility capabilities to capture key vulnerability data. Users can configure custom SmartAttack™ objects to add to the existing pre-crafted library to address new and unique vulnerabilities. Decision support information is at management's fingertips through our reporting and dashboard features.
| Feature |
Starter Edition |
Core Edition |
Professional Edition |
| Extensive SmartAttack Library | 1 SmartAttack | 5 SmartAttacks | Full Library (50+) |
| SmartAttack Updates | partial | partial | complete |
| New SmartAttack Additions | no | no | yes |
| Web Application Assessment | 50 pages | 150 pages | Unlimited |
| Website Traversal Configuration | no | no | yes |
| Assessment Results Reporting | no | 1 report | 10+ reports |
| Pre-Built Assessments | 1 | 1 | extensive |
| Custom Assessments | no | no | yes |
| Intelligent Web Form Training Support | no | no | yes |
| User Administration | no | no | yes |
| Advanced Assessments and Reporting | no | no | yes |
Professional Edition includes the entire SmartAttack™ Library, including updates each month to provide you up-to-date protection on all your web applications. SmartAttacks™ are based on an extensive research performed by the Cenzic Intelligent Analysis (CIA) Research Lab, feedback from various security associations, and input from Global 2000 corporations and government agencies.
The library includes tried and true security practices around resistance to attack. Many of the SmartAttacks™ address security issues for regulatory compliance with Gramm-Leach-Bliley Act (GLBA), Sarbanes-Oxley, SB 1386, HIPAA, and others. Cenzic provides continuous updates based on new vulnerabilities found in our CIA labs, similar to the anti-virus model to help you stay ahead of the exploits and attacks.
Product Overview
Capabilities:
- Enterprise deployment
- Management dashboard and extensive reporting
Differentiators:
- Accuracy:
- Application assessment
- Application specific settings
- Step mode and user injections
- Comprehensiveness:
- Interactive results
- Enhanced Smart Attacks
- Extensibility:
- Rapid configuration of Smart Attack parameters, application specific settings
- Automation:
- Assessment scheduling
- Assessment sharing
- Performance:
- Parallel execution of SmartAttacks™
Enterprise Deployment
- Centralized database for assessment results, reports, application settings and job definitions
- User roles
- Centralized application setting through use of projects
- Job sharing, control over tasks and privileges
- Global dashboard for tracking testing effectiveness
Cenzic Services
 |
ClickToSecure™
- Assessment and Pen-Testing
- Combination of People, Tools and Processes
- Builds policy library for you for repeatable processes
Assessment Methodology
- Process improvement and best practices
Training
- Extensive training to your staff on pen testing and tools
Professional Services
- Implementation and custom policy creation
|